Courseiva
hardMultiple Choice

AIF-C01 Practice Question: A security team needs to detect anomalies in AWS…

A security team needs to detect anomalies in AWS CloudTrail logs to identify potential unauthorized access. They want to use machine learning without manually labeling data or training custom models. Which AWS service should they use?

⚠ Common exam trap

Watch out — candidates often confuse Amazon GuardDuty with Amazon Detective, assuming Detective performs the initial anomaly detection, when in fact Detective is a post-incident investigation tool that consumes findings from GuardDuty and other sources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty

Amazon GuardDuty is a threat detection service that uses machine learning and anomaly detection to continuously monitor AWS CloudTrail logs, VPC Flow Logs, and DNS logs for unauthorized access and malicious activity. It requires no manual labeling of data or custom model training, as it leverages pre-built ML models and integrated threat intelligence to identify suspicious behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Macie

    Why it's wrong here

    Macie uses machine learning to discover and classify sensitive data in Amazon S3, so it never inspects CloudTrail API activity for unauthorised access. It is tempting because it is an ML-powered security service requiring no labelling, but its data-perimeter scope addresses S3 content, whereas the scenario concerns CloudTrail log anomalies.

  • ✗

    Amazon SageMaker

    Why it's wrong here

    SageMaker requires you to build, train and tune models yourself, so it cannot deliver anomaly detection without labelled data or custom training. It is tempting because SageMaker hosts ready-made algorithms, but those still need configuration and training; the scenario demands a pre-trained service such as Amazon GuardDuty.

  • ✓

    Amazon GuardDuty

    Why this is correct

    Amazon GuardDuty continuously analyses CloudTrail management and data events, VPC flow logs and DNS logs using AWS-managed threat intelligence and anomaly detection, raising findings without any labelling or model training by the security team, satisfying the no-custom-model constraint.

  • ✗

    Amazon Detective

    Why it's wrong here

    Detective correlates CloudTrail, VPC flow and GuardDuty findings into behaviour graphs for human investigation, but it does not itself apply machine learning to flag anomalies without labelled data or model training. It is tempting as a security analytics tool, yet its purpose is post-detection triage, not unsupervised anomaly detection.

About these practice questions

This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.